6.5
CVSSv2

CVE-2015-2058

Published: 12/08/2015 Updated: 30/11/2016
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

c2s/c2s.c in Jabber Open Source Server 2.3.2 and previous versions truncates data without ensuring it remains valid UTF-8, which allows remote authenticated users to read system memory or possibly have other unspecified impact via a crafted JID.

Vulnerable Product Search on Vulmon Subscribe to Product

jabberd2 jabberd2

Vendor Advisories

Debian Bug report logs - #779154 CVE-2015-2058 Package: jabberd2; Maintainer for jabberd2 is Debian XMPP Maintainers <pkg-xmpp-devel@listsaliothdebianorg>; Source for jabberd2 is src:jabberd2 (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Tue, 24 Feb 2015 22:09:01 UTC Severity: grave ...